Skip to content

fix(ci): use canonical RevealFleet signer configuration - #511

Merged
RevealUIStudio merged 1 commit into
testfrom
fix/revealfleet-signer-config-20261006
Oct 6, 2026
Merged

RevealUIStudio merged 1 commit into
testfrom
fix/revealfleet-signer-config-20261006

Conversation

@RevealUIStudio

Copy link
Copy Markdown
Owner

The prove-red owner exception now reads only REVEALFLEET_OVERRIDE_SIGNERS, matching the canonical fleet identity. All three language jobs inject that repository variable. An obsolete-only setting cannot grant an exception, and both the canonical and obsolete variables are removed before changed tests execute.

The existing shared signature verifier, exact repository/PR/head/gate/expiry context, request-label ordering and signature namespace remain unchanged. Regression coverage exercises the real CLI and installed shared verifier with synthetic signatures: canonical trust succeeds despite conflicting obsolete data, obsolete-only trust fails closed, and invalid canonical trust cannot fall back. Workflow assertions cover TypeScript, Go and Rust. Owned Git fixtures clear inherited repository-local Git state and prove an unrelated index remains untouched.

Validation:

  • Frozen install completed without dependency changes.
  • Focused maintained prove-red suite: 47 passed, zero skips.
  • pnpm lint: passed across 437 files; five existing warnings and one existing informational diagnostic in unchanged files.
  • pnpm lint:docs and git diff --check: passed.
  • Independent source review: passed.

Sandbox runs could not spawn fixture Git/SSH or lint subprocesses (EPERM); unchanged commands passed with permitted execution outside the sandbox. One initial new fixture assertion incorrectly expected the disposable prove-red checkout to restore source; the fixture now resets its owned source before each case and verifies the existing base-source behavior.

The repository owner still needs to provision and verify the canonical public signer configuration in Actions. Source tests do not establish external variable availability or a live CI grant. This change does not alter repository settings, publish a grant, use an owner exception key, or modify provider configuration.

@RevealUIStudio
RevealUIStudio marked this pull request as ready for review October 6, 2026 03:52
@RevealUIStudio
RevealUIStudio merged commit 4d78ee6 into test Oct 6, 2026
24 checks passed
@RevealUIStudio
RevealUIStudio deleted the fix/revealfleet-signer-config-20261006 branch October 6, 2026 03:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants